# IP Intelligence Briefing: 157.173.126.206/32
## Executive Summary
IP address 157.173.126.206 is a low-risk web server operating within the Contabo infrastructure. No active threat indicators, blacklist entries, or malicious campaign associations were detected during analysis.
## Infrastructure Profile
| Attribute | Details |
|---|---|
| **Risk Score** | 25/100 (Low Risk) |
| **Provider** | Contabo (ASN 51167) |
| **Organization** | Johannes Selg |
| **Network Block** | 157.173.112.0/20 |
| **Geolocation** | Lauterbourg, Grand Est, DE (400km accuracy radius) |
| **Network Role** | Web Server |
| **Infrastructure Type** | VPS Hosting |
## Service Exposure
- Port 80/tcp: HTTP (nginx)
- Port 443/tcp: HTTPS (nginx)
- Port 22/tcp: SSH (OpenSSH_9.6p1 Ubuntu-3ubuntu13.16)
- TLS Certificate: twokstudio.com (Let's Encrypt)
- DNS Resolution: vmi3115672.contaboserver.net
## Threat Indicators
- Blacklist Count: 0
- Abuse Confidence Score: Not applicable
- Known Campaigns: None
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
## Temporal Analysis
Analysis reviewed 26 historical observations spanning from June 16, 2026 through June 21, 2026. The IP demonstrated consistent web server behavior with no evidence of threat persistence or evolving malicious activity. DNS configurations for twokstudio.com include SPF records (v=spf1 include:spf.privateemail.com ~all), though DMARC implementation was not detected.
## Subnet Environment
The /24 subnet (157.173.126.0/24) shows clean classification with zero abuse density and no threat-adjacent neighbors. Contabo infrastructure in this range maintains baseline hosting operations.
## Relationship Graph
34 relationships identified, including:
- Multiple associations with network block TT-20240614
- DNS associations with vmi3115672.contaboserver.net
## Security Assessment
The IP presents minimal risk to defensive operations. No firewall rules or blocking actions are recommended based on current threat intelligence. The address represents legitimate hosting infrastructure for the domain twokstudio.com within Contabo's commercial VPS offering.
## Recommended Actions
No immediate security actions required. Continue standard monitoring for any changes in network role, threat indicators, or reputation metrics.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | TT-20240614 |
| CIDR Block | 157.173.112.0/20 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3115672.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi3115672.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 1/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | twokstudio.comwww.twokstudio.com |
| Valid From | 2026-05-05T11:58:10+00:00 |
| Valid Until | 2026-08-03T11:58:09+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 05E6996A537B6113A65D9F01B8FBF88F1721 |
| Thumbprint | 17DCA5C22EC25E8C95925A0CC33F714CE19691F2 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-30 10:58:11 UTC |
| Last Seen | 2026-06-21 05:19:52 UTC |
| Profile Built | 2026-06-21 05:29:40 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 26 |
Full dossier details are available via our API.